Splunk Search

Why is data summary not displaying?

akankshayadav
Path Finder

When I am click on my data summary, it is not displaying anything just showing

akankshayadav_0-1625829593402.png

Any suggestions?
Thanks.

0 Karma

aliazaad
New Member

if you select index=main for your input 

the problem will be solved

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @akankshayadav,

I haven't your issue in my Splunk, which version are you using?

My only hint is to open a Case To Splunk Support.

Ciao and Happy Easter.

Giuseppe

0 Karma

state_larson_ti
Path Finder

Actually a little more searching and I found the answer here (https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-...). I also on my experimental/learning box (latest version) had enabled (under Settings -> Roles -> Admin -> Indexes) the * (All non-internal indexes) and the _* (All internal indexes) to be default and this immediately allowed data summary to work and see all the indexes.  I can see how, by default, you might not want to have this enabled for the admin account.

I think in courses you do, they may enable this by default for your accounts on non-internal indexes to make it easier for you to configure things, so I had not had to configure it myself.

state_larson_ti
Path Finder

Good Day.  I was curious if you had ever found an answer here.  I noticed the same thing, logged in about 3 days later, and the data had been populated (but not for the data I had put in the day before.  I assume there is a search that populates this data, but it only runs maybe 1/x per day or week.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...